domain-osint
Installation
SKILL.md
Domain OSINT
Map a domain's attack surface and ownership from public sources. Input: a domain, hostname, or IP. Passive by default — no scanning of the target's systems without written authorization.
Step 1 — Authorized scope
Read ../../ETHICS.md. Passive lookups (DNS, CT logs, archives) are generally fine; active scanning/probing needs authorization. Note the scope and stay on the passive side unless cleared. Done when noted.
Step 2 — Ownership & records
Run whois-dns-recon: WHOIS/RDAP registrant and dates, nameservers, MX, SPF/
DKIM/DMARC, and full DNS record set. Note the registrar and hosting ASN. Done
when registration and DNS records are captured with lookup timestamps.